Description
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Mozilla / Firefox3.5 – 3.5
- Mozilla / Firefox3.5.1 – 3.5.1
- Mozilla / Firefox3.5.2 – 3.5.2
- Mozilla / Firefox3.5.3 – 3.5.3
- Mozilla / Firefox3.5.4 – 3.5.4
- Mozilla / Firefox3.5.5 – 3.5.5
- Mozilla / Firefox3.5.6 – 3.5.6
- Mozilla / Firefox3.5.7 – 3.5.7
- Mozilla / Firefox3.5.8 – 3.5.8
- Mozilla / Firefox3.5.9 – 3.5.9
- Mozilla / Firefox3.5.10 – 3.5.10
- Mozilla / Firefox3.5.11 – 3.5.11
- Mozilla / Firefox3.5.12 – 3.5.12
- Mozilla / Firefox3.5.13 – 3.5.13
- Mozilla / Firefox3.5.14 – 3.5.14
- Mozilla / Firefox3.6 – 3.6
- Mozilla / Firefox3.6.2 – 3.6.2
- Mozilla / Firefox3.6.3 – 3.6.3
- Mozilla / Firefox3.6.4 – 3.6.4
- Mozilla / Firefox3.6.6 – 3.6.6
- Mozilla / Firefox3.6.7 – 3.6.7
- Mozilla / Firefox3.6.8 – 3.6.8
- Mozilla / Firefox3.6.9 – 3.6.9
- Mozilla / Firefox3.6.10 – 3.6.10
- Mozilla / Firefox3.6.11 – 3.6.11
- Mozilla / seamonkey2.0.9 – 2.0.9
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0.1 – 2.0.1
- Mozilla / seamonkey2.0.2 – 2.0.2
- Mozilla / seamonkey2.0.3 – 2.0.3
- Mozilla / seamonkey2.0.4 – 2.0.4
- Mozilla / seamonkey2.0.5 – 2.0.5
- Mozilla / seamonkey2.0.6 – 2.0.6
- Mozilla / seamonkey2.0.7 – 2.0.7
- Mozilla / seamonkey2.0.8 – 2.0.8
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / seamonkey2.0 – 2.0
- Mozilla / Thunderbird3.0.2 – 3.0.2
- Mozilla / Thunderbird3.0.3 – 3.0.3
- Mozilla / Thunderbird3.0.4 – 3.0.4
- Mozilla / Thunderbird3.0.5 – 3.0.5
- Mozilla / Thunderbird3.0.6 – 3.0.6
- Mozilla / Thunderbird3.0.7 – 3.0.7
- Mozilla / Thunderbird3.0.8 – 3.0.8
- Mozilla / Thunderbird3.0.9 – 3.0.9
- Mozilla / Thunderbird3.1.1 – 3.1.1
- Mozilla / Thunderbird3.1.2 – 3.1.2
- Mozilla / Thunderbird3.1.3 – 3.1.3
- Mozilla / Thunderbird3.1.4 – 3.1.4
- Mozilla / Thunderbird3.1.5 – 3.1.5
- Mozilla / Thunderbird3.0.1 – 3.0.1
Exploits & proofs of concept
- exploit-dbMozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit)by Metasploit
- exploit-dbMozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' / 'appendChild' Remote Overflowby anonymous
- exploit-dbMozilla Firefox - Simplified Memory Corruption (PoC)by extraexploit
- exploit-dbMozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial of Serviceby Daniel Veditz
References
- MISChttp://www.securityfocus.com/bid/44425
- MISChttps://rhn.redhat.com/errata/RHSA-2010-0812.html
- MISChttps://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/2837
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=646997
- MISChttp://support.avaya.com/css/P8/documents/100114335
- VENDOR_ADVISORYhttp://secunia.com/advisories/41965
- VENDOR_ADVISORYhttp://secunia.com/advisories/41975
- MISChttp://www.redhat.com/support/errata/RHSA-2010-0896.html
- MISChttp://www.redhat.com/support/errata/RHSA-2010-0808.html
- EXPLOIThttp://www.exploit-db.com/exploits/15341
- MISChttp://www.securitytracker.com/id?1024651
- VENDOR_ADVISORYhttp://secunia.com/advisories/41761
- MISChttps://bugzilla.mozilla.org/show_bug.cgi?id=607222
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html
- MISChttp://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter
- VENDOR_ADVISORYhttp://secunia.com/advisories/41969
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/USN-1011-3
- MISChttp://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
- MISChttp://www.norman.com/about_norman/press_center/news_archive/2010/129223/
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/usn-1011-1
- MISChttp://www.securitytracker.com/id?1024650
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/USN-1011-2
- MISChttp://www.redhat.com/support/errata/RHSA-2010-0809.html
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:219
- VENDOR_ADVISORYhttp://secunia.com/advisories/42867
- MISChttp://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/2857
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2011/0061
- MISChttp://support.avaya.com/css/P8/documents/100114329
- VENDOR_ADVISORYhttp://www.debian.org/security/2010/dsa-2124
- MISChttp://www.securitytracker.com/id?1024645
- VENDOR_ADVISORYhttp://secunia.com/advisories/42043
- MISChttp://www.norman.com/security_center/virus_description_archive/129146/
- VENDOR_ADVISORYhttp://secunia.com/advisories/41966
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:213
- VENDOR_ADVISORYhttp://secunia.com/advisories/42008
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html
- MISChttp://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/2871
- MISChttp://isc.sans.edu/diary.html?storyid=9817
- MISChttp://www.redhat.com/support/errata/RHSA-2010-0810.html
- MISChttp://www.mozilla.org/security/announce/2010/mfsa2010-73.html
- EXPLOIThttp://www.exploit-db.com/exploits/15352
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108
- VENDOR_ADVISORYhttp://secunia.com/advisories/42003
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html
- MISChttp://www.redhat.com/support/errata/RHSA-2010-0861.html
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html
- EXPLOIThttp://www.exploit-db.com/exploits/15342
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/2864
Updated 15m ago · 8 sources